CVE-2010-4261
Off-by-one error in the icon_cb function in pe_icons.c in libclamav in ClamAV before 0.96.5 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unspecified vectors.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (4.77%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Off-by-one error in the icon_cb function in pe_icons.c in libclamav in ClamAV before 0.96.5 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unspecified vectors. NOTE: some of these details are obtained from third party information.
- CVSS 2.0
- 7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
- EPSS
- 4.77% probability · 91th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-189
- Affected
- clamav/clamav
- Source
- secalert@redhat.com
References
- http://git.clamav.net/gitweb?p=clamav-devel.git%3Ba=blob_plain%3Bf=ChangeLog%3Bhb=master
- http://lists.apple.com/archives/security-announce/2011/Mar/msg00006.html
- http://lists.fedoraproject.org/pipermail/package-announce/2010-December/051905.html
- http://lists.fedoraproject.org/pipermail/package-announce/2010-December/052401.html
- http://lists.opensuse.org/opensuse-security-announce/2010-12/msg00006.html
- http://openwall.com/lists/oss-security/2010/12/03/1
- http://openwall.com/lists/oss-security/2010/12/03/3
- http://openwall.com/lists/oss-security/2010/12/03/6
- http://secunia.com/advisories/42426Vendor Advisory
- http://secunia.com/advisories/42523Vendor Advisory
- http://secunia.com/advisories/42555
- http://secunia.com/advisories/42720
- http://support.apple.com/kb/HT4581
- http://www.mandriva.com/security/advisories?name=MDVSA-2010:249
- http://www.securityfocus.com/bid/45152
- http://www.securitytracker.com/id?1024818
- http://www.ubuntu.com/usn/USN-1031-1
- http://www.vupen.com/english/advisories/2010/3135Vendor Advisory
- http://www.vupen.com/english/advisories/2010/3137Vendor Advisory
- http://www.vupen.com/english/advisories/2010/3185
- http://xorl.wordpress.com/2010/12/05/cve-2010-4261-clamav-icon_cb-off-by-one/
- https://bugzilla.redhat.com/show_bug.cgi?id=659861
- https://wwws.clamav.net/bugzilla/show_bug.cgi?id=2344
- http://git.clamav.net/gitweb?p=clamav-devel.git%3Ba=blob_plain%3Bf=ChangeLog%3Bhb=master
- http://lists.apple.com/archives/security-announce/2011/Mar/msg00006.html
- http://lists.fedoraproject.org/pipermail/package-announce/2010-December/051905.html
- http://lists.fedoraproject.org/pipermail/package-announce/2010-December/052401.html
- http://lists.opensuse.org/opensuse-security-announce/2010-12/msg00006.html
- http://openwall.com/lists/oss-security/2010/12/03/1
- http://openwall.com/lists/oss-security/2010/12/03/3
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.